Company

All roles

IAM Solutions Architect

  • Department: Technical Consulting
  • Location: United States
  • Work type: Remote
Apply for this role

The Role

Palyrian’s immediate need is for IAM Solutions Architects to lead non-human identity (NHI) program builds for enterprise clients. Machine identities, workloads, service accounts, API credentials, and now AI agents have quietly outgrown the controls that were designed for people. Very few organizations have a dedicated NHI program today. That is changing fast, and Palyrian is being pulled into the build.

We are not expecting you to have run an NHI program already. The space is too new for that to be a fair filter. We are looking for strong solutions architects from adjacent identity domains (IGA, PAM, IDP/AuthN) who are already doing this job somewhere else in the identity stack. You would be doing the same work in a newer domain, and Palyrian provides the NHI and platform-specific enablement to get you there.

Alongside the NHI work you will architect on SailPoint engagements (IdentityIQ and Identity Security Cloud), which remain a core part of the practice. Breadth is the point here: we are looking for architects who want to touch more than one platform, not fewer.

About Palyrian

Palyrian is an identity services boutique founded in 2024 by three practitioners who spent years building and running enterprise identity programs together. The firm exists on a simple premise: most IAM programs have the right tools, but few have the right people. Palyrian brings the quality of a large firm with the speed of a small one, and its vision is to be the most trusted identity services boutique in the market: a focused firm clients return to because the work holds up, not because of a contract.

Palyrian works across SailPoint (IdentityIQ and Identity Security Cloud), Oasis, Veza, and C1 (formerly ConductorOne). The team treats identity as a system, not a stack of tools, and favors fixing what a client already owns before recommending something new. It is a boutique that runs like a tech startup: small, fast, and light on process.

What You Will Do

  • Discover and inventory the non-human identity estate: what exists across the enterprise, where it lives, what it is used for, who owns it, and how it authenticates.
  • Define NHI reference architecture covering the full lifecycle — creation, ownership, credential and secret management, rotation, attestation, and decommissioning.
  • Work fluently across the three classes of identity (workforce, customer, non-human) and across the full range of NHI types: workloads, machine identities, service accounts, API credentials, bots, and AI agents.
  • Map the control landscape for AI agents: the different agent types, their lifecycles, and where the controls for each one sit. This is where a lot of the client's interest is heading.
  • Produce complete artifacts for architecture review boards and cyber security reviews — reference architecture diagrams, data and process flows, and detailed security diagrams.
  • Lead program assessments, vendor and tool evaluations, future-state architecture, governance model design, platform architecture reviews, and product health checks.
  • Support identity engagements with roadmap, architecture, and executive-level communication.
  • Own solution architecture and design authority on NHI platform implementations and SailPoint engagements.
  • Lead design sessions and proofs of concept. Make decisions the engineering team builds against and write them down.
  • Define integration patterns, data models, access models, and non-functional requirements — security, scale, resiliency, and performance.
  • Walk the client through the solution and progress towards design adoption. This takes more repetitions than getting it right does.
  • Stay technical enough to unblock hard problems. This is not a heads-down build role, but it is not a slide-deck role either.
  • Evolve the NHI program as the estate moves underneath it — new workloads, new agents, new platforms, new regulatory attention.
  • Guide certification strategy, configuration and tuning, and program reporting so the program improves rather than decays.
  • Lead knowledge transfer and operating-model design so client teams can eventually run it themselves.

What You Bring

  • 8+ years in identity and access management, with meaningful time as a solutions architect, technical lead, or principal engineer in at least one identity domain.
  • Depth in one or more of: identity governance (SailPoint IdentityIQ or ISC, Saviynt), privileged access (CyberArk, Delinea, BeyondTrust), or identity provider and authentication platforms (Okta, Microsoft Entra ID, Ping). Breadth across more than one is a strong plus. A purely single-threaded background is the thing most likely to give us pause.
  • Strong command of the IAM service toolset and what each category genuinely does: governance, privileged access, secrets management, certificate management, authentication including MFA and identity providers, and authorization. A real grasp of the three classes of identity (workforce, customer, and non-human) and of NHI types beyond the familiar ones.
  • The ability to walk into an enterprise and identify its non-human identities and the characteristics around them. Knowing which common tools give visibility into NHI lifecycle is a differentiator.
  • A working understanding of the different types of AI agents, their lifecycles, and where the controls for each sit. We do not expect you to have governed an agent fleet ; we do expect you to reason about it credibly.
  • Ability to create and deliver complete artifacts for ARB and cyber review, including detailed security diagrams and not only high-level pictures.
  • Genuine client-facing range. You can hold your own in a technical conversation with a client’s cloud architect and then explain the same decision in plain language to a stakeholder who is not an engineer.
  • The ability to tell a client what is wrong, why it is wrong, and how you will fix it, including the diplomatic version of that conversation, when the client is asking for something that is not the right answer.
  • Comfort operating on your own. On smaller engagements you may be the only Palyrian person in the room, and to that client you are the firm.
  • Energy and patience. Walking a customer through the same solution several times without getting frustrated matters as much here as being the smartest person on the call.
  • Evidence that you build and learn outside your day job; a home lab, a side project, something you taught yourself recently. It does not need to be identity related.
  • S. based and authorized to work in the United States.

What You Do Not Need

Worth stating plainly, because these are the four reasons good candidates screen themselves out of this role:

  • Direct NHI program experience. Most organizations do not have dedicated NHI programs yet, so almost nobody has this. If you are a strong architect in an adjacent identity domain, we will train you on the NHI and platform-specific material — expect a structured internal enablement program before you are client-facing on it.
  • SailPoint certifications and other credentials help us find you when we are scanning, and we sponsor them once you are here, but we hire on demonstrated delivery rather than badges.
  • Heavy hands-on-keyboard coding. Architects here are generally not writing custom scripts all day. You do need real technical depth and a working command of enterprise infrastructure — enough that a client-side architect never wonders whether you belong in the conversation.
  • A previous architect title. If you came to consulting or sales engineering from a hands-on engineering role and kept the technical range, that background can fit well.

Nice to Have

  • Hands-on experience with NHI, machine identity, or secrets platforms (Oasis, Veza, C1, or comparable tools).
  • SailPoint IdentityIQ or Identity Security Cloud architecture and delivery experience.
  • Secrets management at scale (HashiCorp Vault, cloud-native secret stores) and certificate lifecycle management.
  • Cloud identity depth across AWS, Azure, or GCP, including workload identity and federation patterns.
  • Experience contributing to proposals, statements of work, and scoping. We would like a few people on the team who can do this, but it is a nice-to-have rather than a requirement for every hire.
  • Regulated-industry experience — financial services, healthcare, or federal — and the audit expectations that come with it.
  • Zero Trust architecture experience, and familiarity with how NHI and agentic identity fit into it.

A Note on Certifications

Certifications are a filter for finding people, not a proxy for competence. If you hold SailPoint, CyberArk, Okta, Entra, CISSP, or similar credentials, list them — they help. If you do not, and you can describe the programs you built and the decisions you made, that carries more weight with us.

Once you are here, Palyrian funds training and certification across SailPoint and the NHI platforms we work with, including the enablement that brings you up to speed on Oasis.

Who Thrives Here

Palyrian is a services boutique that runs like a tech startup. Identity must be your thing. The team lives by four principles:

  • Builder's Mindset. When you see a better way, you build it. Problems don’t come with answers attached.
  • Own the Outcome. You are accountable for whether the client’s program improves, not just whether the ticket closed.
  • Always Be Learning. Identity changes fast, and non-human identity changes faster. You keep pace and bring what you learn back to the team.
  • Prideful Excellence. Work that holds up after we leave. Clients return because of the quality, not the contract.

One more thing, because it is the single most common way a strong resume turns into a poor fit: the person we are not looking for is the brilliant engineer who has been heads-down in the code for years, has reached architect-level knowledge, and cannot explain any of it to another human being. The technical bar here is real. The communication bar is equally real, and we do not trade one against the other.

Hiring Process

  1. An introductory conversation and initial screen
  2. A technical interview with Palyrian. Expect roughly 30-45 minutes of systems-thinking and scenario questions rather than a live coding exercise. This is the first real gate.
  3. A behavioral and culture conversation with one of the founders.

We try to keep them inside a single hour where we can. We would rather move quickly than run you through a gauntlet.

Benefits

  • Remote-first, U.S. based. Flexible hours, with client time zones taking priority when an engagement calls for it.
  • 20 days of paid time off, granted as a bucket rather than accrued, plus holidays.
  • Medical, dental, and vision coverage through Aetna.
  • 401(k) with company match: full match on the first 3% and half match on the next 2%.
  • Annual performance-based bonus eligibility.
  • Sponsored training and certifications, including platform-specific enablement.
  • Direct client work, real ownership, and a seat at a boutique early enough that your work shapes the firm.

Questions about this role?Email careers@palyrian.com